General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Destination NAT/PAT clarification

Prior to shooting myself in the foot I want to make sure I'm on the right track.

I have an application where I'd like to take inbound connections directed at a particular port on my untrusted "outside" FW interface and redirect them to the same port o

...

MCmgt by L2 Linker
  • 5824 Views
  • 8 replies
  • 1 Likes

Resolved! Google Mail for Business

Hi all,

Anyone has experience in using SSL decryption with Google Mail for Business? My concerns are the incoming emails will no longer go thru our mail content filtering engine and we don't have adequate tools to prevent data loss in outgoing mails (

...

Resolved! Question regarding ARP timeout

Hi,

I have a question regarding ARP caching and timeout on the Palo Alto platform.

Based on the output of the "show arp all" command, it looks as if the "default timeout" is 1800 seconds.  I am doing some work with failover for a cluster inside my fire

...

dsulli99 by Not applicable
  • 2833 Views
  • 1 replies
  • 0 Likes

Firewall is doing packet captures on it's own

Hi,

I just noticed two traffic log entries that had packet captures attached. I didn't enable this anywhere, and just to make sure, I just went through the whole config (all profiles) to make sure I didn't enable it by accident. Are thre any circumsta

...

Groups that the user belongs to

Hi,

When we want to look at ip address of a user

show user ip-user-mapping ip  ........

Groups that the user belongs to (used in policy) comes empty.

I tried

debug user-id refresh group-mapping all

Also I can see all gorups on group mapping.

panos by L6 Presenter
  • 2153 Views
  • 4 replies
  • 0 Likes

TS Agent on Citrix XenApp 6.0 farm

Hello,

Our XenApp farm IP range is dynamic and the servers could spin up on any number of IPs within a couple of segments.  Does a TS Agent entry for every single possible IP need to be added on the PAN device, or can I configure it to look at a subne

...

CRHC by L4 Transporter
  • 3649 Views
  • 3 replies
  • 1 Likes

Resolved! How does SSL inbound decryption work exactly?

I am not looking for a guide on how to configure it, there are plenty. What I want to know is how SSL inbound decryption works from an architectural point of view. In the docs it says that once you loaded the webserver's certificate onto the PAN devi

...

Radius Authentication

Hi,

we use Vpn authentication for portal LDAP and for gateway Radius

Users can connect using their names to portal with typing user and password

after that they type another user name and password for Radius.

When we look we see the logs of users coming

...

panos by L6 Presenter
  • 2106 Views
  • 4 replies
  • 0 Likes

Resolved! Excel XLSX recognized as ZIP file

Hello,

I configured a File Blocking profile to block specific file format (like Exe, PE, RAR, etc).

Unfortunately, this profile also blocks Excel file in new format (.XLSX).

No problem, with the old format (.XLS) !!

After reading some doc, it seems that

...

licenselu by L4 Transporter
  • 5268 Views
  • 2 replies
  • 1 Likes

Resolved! Not Receiving Scheduled Reports

Kind stumped on this one. I have some scheduled reports I'm not receiving. I was getting them on a daily basis as configured in the email scheduler but they just stopped one day and no changes to the firewall were made. I've created a report group, a

...

Palo Alto as a route reflector

Hi,

I have a couple of PA-500 clusters and I want to use them as route reflectors for my internal BGP network. There doesn't seem to be anything in the documentation on how to do this but the documentation suggests the Palo will do it, I was wondering

...

Gareth by L1 Bithead
  • 3387 Views
  • 5 replies
  • 0 Likes

Resolved! Some has a problem blocking Youtube Application?

I recently had problems with blocking youtube, I added a policy where I deny the application access to youtube. When I go to the YouTube page and I try to watch a video, the first time if it hangs correctly, but if I try more times with other videos,

...

Resolved! DNS proxy policy

when you create a dns Proxy policy you declare only the ingress interface

or egress interface ?

Gregoux by L4 Transporter
  • 2594 Views
  • 3 replies
  • 0 Likes

Resolved! group member attribute

when you create a ldap profile by default

the group member attribute is defined to member

my question is

member for palo does mean "memberOf" for Ldap group attribute.

and in this way each autentication request is answer with all users nested groups  

...

Gregoux by L4 Transporter
  • 3456 Views
  • 4 replies
  • 0 Likes

https coaching page - Connexion reset depend of browser

Hi all,

Configure a continue action on certain url category. If request in made in http no issue. If request is made in https, depend of your browser, I have

- Chrome V27.0.1453.110 m => erroe page with connexion reset

- FireFox V21 => erroe page with

...

VinceM by L5 Sessionator
  • 2646 Views
  • 5 replies
  • 0 Likes
  • 23707 Posts
  • 103 Subscriptions
Top Solution Authors
Top Liked Authors
Labels